PatchSiren

siemens CVE debriefs · Page 66

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Siemens CVE published 2017-03-02

CVE-2017-2685

CVE-2017-2685 is a Siemens SINUMERIK issue affecting specific Integrate Operate Client versions, where an attacker in a man-in-the-middle position could read and manipulate data in TLS sessions. The CVE was publicly published on 2017-03-01 and is rated CVSS 7.4 (HIGH).

MEDIUM Siemens CVE published 2017-02-28

CVE-2017-2683

CVE-2017-2683 is a high-severity persistent cross-site scripting issue in Siemens RUGGEDCOM NMS. The vulnerability is described as affecting the web application on ports 8080/TCP and 8081/TCP, where a non-privileged user could inject persistent script content and potentially gain administrative permissions. The issue was published on 2017-02-27 and is classified as CWE-79.

HIGH Siemens CVE published 2017-02-28

CVE-2017-2682

CVE-2017-2682 is a cross-site request forgery (CSRF) issue in Siemens RUGGEDCOM NMS web management interfaces. According to the NVD record and Siemens references, a remote attacker could cause administrative actions to execute if a targeted user had an active session and could be induced to submit a malicious request. The issue is rated HIGH with a CVSS 3.0 score of 8.8, reflecting network reachability, n [truncated]

CRITICAL Siemens CVE published 2017-02-13

CVE-2017-2684

CVE-2017-2684 affects Siemens SIMATIC Logon prior to V1.5 SP3 Update 2. According to the vendor and NVD records, an attacker who already knows a valid user name and has physical or network access to the affected system could bypass application-level authentication. NVD rates the issue Critical with CVSS 3.0 vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H.

CRITICAL Siemens CVE published 2016-09-04

CVE-2016-8567

CVE-2016-8567 describes a critical authentication weakness in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in affected installations, and an attacker may gain privileged access to the database over port 2638/TCP. Because the issue is network-reachable and involves fixed credentials, it is especially important for industrial environments that expose or rely on SICAM [truncated]

HIGH Siemens CVE published 2016-09-04

CVE-2016-8566

CVE-2016-8566 is a credential-handling weakness in Siemens SICAM PAS before 8.00. According to the NVD record, an authenticated local attacker with certain privileges could possibly reconstruct passwords used by users to access the database. The issue was publicly disclosed on 2017-02-13 and later updated in the NVD record on 2026-05-13. Because the impact includes exposure of database access credentials, [truncated]

HIGH Siemens CVE published 2016-07-29

CVE-2016-7987

CVE-2016-7987 is a network-reachable denial-of-service issue affecting Siemens ETA4 firmware prior to Revision 08 on the SM-2558 extension module used with SICAM AK, SICAM TM 1703, SICAM BC 1703, and SICAM AK 3. According to the supplied record, specially crafted packets sent to TCP port 2404 can cause the device to enter defect mode, and recovery may require a cold start. NVD rates the issue as CVSS 7.5 [truncated]